Some cookies are necessary for SecondDoor to work. Others are optional, and tell us how the site and the product are used. Accept all, or decline all optional ones. Without a selection, nothing optional is set. More in our cookie policy.
Basic scanSoftware and storefront · Storefront property/Scanned 8 Sept 2026, 02:32 UTC/1 browser pass
A software and storefront hybrid with strong machine discoverability but no published path for agents to complete a purchase.
Narrow. Both audiences hit roughly the same walls.
Ordered by what the evidence says is costing most. Written for whoever owns the site, not whoever builds it.
3 pieces of evidence and the recommended fix are recorded for this issue, with /shipping written from your own pages.
This is a basic scan, so it raises the three issues the deterministic evidence supports. A deep scan sends two agents over the site and raises up to ten, each with cited evidence and the screens to prove it.
A deep scan walks the site with two agents, records cited evidence and screenshots, and keeps a mission timeline. It comes with the paid plans. Making an account costs nothing and gives you one basic scan a month.
The score and the audit trail stay public. The evidence and the files open with an account.
The audit trail behind every number above. Not measured is not zero.
Machine discoverability
Robots.txt names and allows 14 AI crawlers including GPT, Claude, Perplexity and Gemini. A real browser is served the page normally. The sitemap lists 92 URLs, the homepage carries 6 schema.org types, llms.txt is published, and comparison.
4 observations recorded.
Programmatic onboarding
A machine readable API spec is published.
3 observations recorded.
Pricing legibility
Six prices are readable without JavaScript on the pricing page: $0, $29, $99, $249, $2,500 and an unlabeled tier. No tier is gated behind a demo or contact-sales wall. The page carries FAQ schema.
2 observations recorded.
Agent-aware instrumentation
An MCP manifest is published at /.well-known/mcp.json, an ai-plugin.json is published, robots.txt explicitly names 14 AI crawlers and allows them, and an OpenAPI spec is published.
4 observations recorded.
Machine-fetchable trust
Security.txt is published with a contact route for machines. The returns policy reads as text at /refunds without JavaScript. The homepage answers automated requests.
3 observations recorded.
Commercial rails
Prices are published in raw HTML on the pricing page and the homepage carries 13 prices in structured data. A self-serve signup form is 2 steps from the homepage with 2 required fields and Google SSO.
4 observations recorded.
Steps to first value
The primary call to action, 'Sign up for free', is 2 steps from the homepage and leads to a 2-field signup form. No payment is asked at signup. A visitor can reach the form and begin onboarding quickly, though the walk did not measure what.
1 observation recorded.
Required fields
The signup form asks 2 fields, both required: Work email and Password. One sign-in option is offered: Google. Both inputs carry validation rules. The form is minimal and does not ask for unnecessary detail.
1 observation recorded.
Verification walls
No verification requirement appears on the signup page itself. Google SSO is offered as an alternative to password entry, which avoids email verification entirely for those users.
1 observation recorded.
Error recovery
Both of the 2 inputs on the signup form carry validation rules, so a user can see what is expected before submission. The walk did not measure inline error messages or live regions that would guide recovery after a failed attempt.
1 observation recorded.
It got through 16 of 18.
The agent got through 16 of 18 requests, but could not find out whether verified agents are recognised. It came up empty on 1 other check too.